Skip to content

Must-use plugin (mu-plugin)

A must-use plugin is a PHP file in wp-content/mu-plugins that WordPress runs on every request. It is always on, cannot be deactivated from the dashboard and gets no update notices, so it is the plugin most easily overlooked.

By
WP Ministry
Published

In short

  • A must-use plugin is any PHP file directly inside wp-content/mu-plugins. It runs without being activated and has no "Deactivate" link.
  • Switching every plugin off does not switch these off. If a fault survives that test, look here and at drop-ins.
  • WordPress shows no update notice for them. Know who put each one there and who keeps it current.

A must-use plugin, or mu-plugin, is a plugin that WordPress runs without anyone activating it. It is a PHP file placed directly in the folder wp-content/mu-plugins. WordPress loads every such file on every request, in alphabetical order, before the ordinary plugins. The dashboard has no switch for it. To turn one off, you move the file out of the folder.

Hosting companies use them for their own caching and monitoring code, and developers for code that nobody should switch off by accident.

Where you meet it

  • On the Plugins screen. Go to Plugins, then Installed Plugins. Must-use plugins are not in the main list or its count. When the folder holds at least one, a link named "Must-Use" appears above the table. That view says "Files in the /wp-content/mu-plugins directory are executed automatically." Its rows have no "Deactivate" and no "Delete".
  • In Site Health. Tools, then Site Health, then the Info tab lists them under "Must Use Plugins".
  • In the files. WordPress loads only files that end in .php and sit directly in wp-content/mu-plugins. A plugin in a subfolder runs only if a file in the main folder loads it.

What goes wrong

A fault is still there with every plugin switched off. Deactivating all plugins, renaming the plugins folder and WP-CLI's --skip-plugins all leave must-use plugins running. Check them before you rule plugins out: see how to find and fix a plugin conflict. If you cannot reach the dashboard, see how to deactivate plugins when you are locked out.

One is out of date and nobody noticed. A must-use plugin shows no update notice and is not updated from the dashboard. Whoever put it there has to replace the file by hand.

Nobody knows why it is there. On a site you have inherited, list them and find out who maintains each. The client site takeover checklist has the step.

It hides something. A file here runs on every page and is on no list most owners look at, so a backdoor can sit in this folder after a break-in. A must-use plugin is not a sign of one by itself. The file to look into is one that neither you, your developer nor your host can explain: see why a site keeps getting hacked. Ask the host before removing a file it installed, because the site may depend on it.

Drop-ins are something else

A drop-in is a single file with a fixed name, placed directly in wp-content, that replaces or adds to one part of WordPress itself. object-cache.php supplies an external object cache. advanced-cache.php is a caching layer, used only when WP_CACHE is true. db.php is a custom database class.

A must-use plugin can have any file name and do anything a plugin does. A drop-in counts only under its exact name, and each name has one job. The Plugins screen lists them under a link of their own, "Drop-ins", or "Drop-in" when there is one.

How to look at yours

With WP-CLI:

bash
wp plugin list --status=must-use

Each file in the folder gets a row whose status reads must-use. Headings with no rows mean there are none. Change the status to dropin to list drop-ins.

Common questions

How do I turn off a must-use plugin?

Move its file out of wp-content/mu-plugins, or rename it so that the name no longer ends in .php. Keep the file so that you can put it back.

What does "mu" stand for?

It first stood for WordPress MU, the multi-user version of WordPress, where the folder began. The feature later became part of every WordPress site. The short name stayed and was reread as "must-use".

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.